5682 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-1841
MPA2 Access Panel Web
8.1
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Honeywell MPA2 Access Panel (Web server modules) allows XSS Using Invalid Characters.This issue affects MPA2 Access Panel all version prior to R1.00.08.05.  Honeywell released firmware update package MPA2 firmware R1.00.08.05 which addresses this vulnerability. This version and all later versions correct the reported vulnerability.

CVE-2023-0789
thorsten/phpmyfaq Web
8.1
HIGH
EPSS
7.8%
2023 CWE-77 1 PoC

Command Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

CVE-2023-20894
VMware vCenter Server (vCenter Server) General
8.1
HIGH
EPSS
45.9%
2023 1 PoC

The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.

CVE-2023-1760
thorsten/phpmyfaq Web
8.1
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE-2023-23567
ImageGear General
8.1
HIGH
EPSS
0.2%
2023 CWE-119 1 PoC

A heap-based buffer overflow vulnerability exists in the CreateDIBfromPict functionality of Accusoft ImageGear 20.1. A specially crafted file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2023-20938
Android General
8.1
HIGH
EPSS
0.2%
2023 1 PoC

In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-257685302References: Upstream kernel

CVE-2023-0787
thorsten/phpmyfaq Web
8.1
HIGH
EPSS
0.3%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

CVE-2023-21828
Hospitality Reporting and Analytics Web Database
8.1
HIGH
EPSS
0.8%
2023 1 PoC

Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Hospitality Reporting and Analytics. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Reporting and Analytics accessible data as well as unauthorized access to critical data or complete acce

CVE-2023-4899
mintplex-labs/anything-llm Database
8.1
HIGH
EPSS
0.1%
2023 CWE-89 1 PoC

SQL Injection in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.

CVE-2023-3314
Enterprise Security Manager General
8.1
HIGH
EPSS
0.6%
2023 CWE-78 1 PoC

A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external commands used to control the process execution of the .zip application allows an authorized user to obtain control of the .zip application to execute arbitrary commands or obtain elevation of system privileges.

CVE-2023-52043
Software Genérico General
8.1
HIGH
EPSS
0.1%
2023 1 PoC

An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wireless Access Point Passwords (WPA-PSK) allowing an attacker to gain unauthorized network access via weak authentication controls.

CVE-2023-3191
nilsteampassnet/teampass Web
8.1
HIGH
EPSS
0.1%
2023 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

CVE-2023-0994
francoisjacquet/rosariosis General
8.1
HIGH
EPSS
0.4%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository francoisjacquet/rosariosis prior to 10.8.2.

CVE-2023-28505
UniData Web
8.1
HIGH
EPSS
0.4%
2023 CWE-120 1 PoC

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the length. This requires a valid login to exploit.

CVE-2023-50447
Software Genérico General
8.1
HIGH
EPSS
0.7%
2023 2 PoCs

Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter).

CVE-2023-5397
Experion Server General
8.1
HIGH
EPSS
0.3%
2023 CWE-20 1 PoC

Server receiving a malformed message to create a new connection could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-5401
Experion Server General
8.1
HIGH
EPSS
1.6%
2023 CWE-121 1 PoC

Server receiving a malformed message based on a using the specified key values can cause a stack overflow vulnerability which could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.

CVE-2023-0441
Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery Web Windows
8.1
HIGH
EPSS
0.4%
2023 1 PoC

The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenticated users, such as subscriber. The callback function allows numerous actions, the most serious one being reading and updating the WordPress options which could be used to enable registration with a default administrator user role.

CVE-2023-26984
Software Genérico General
8.1
HIGH
EPSS
0.8%
2023 1 PoC

An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted request.

CVE-2023-45839
Buildroot General
8.1
HIGH
EPSS
0.1%
2023 CWE-494 2 PoCs

Multiple data integrity vulnerabilities exist in the package hash checking functionality of Buildroot 2023.08.1 and Buildroot dev commit 622698d7847. A specially crafted man-in-the-middle attack can lead to arbitrary command execution in the builder.This vulnerability is related to the `aufs-util` package.